US7302571B2ExpiredUtilityA1

Method and system to maintain portable computer data secure and authentication token for use therein

Assignee: UNIV MICHIGANPriority: Apr 12, 2001Filed: Apr 9, 2002Granted: Nov 27, 2007
Est. expiryApr 12, 2021(expired)· nominal 20-yr term from priority
G06F 21/35G06F 21/6227G06Q 20/3674G06F 21/43
84
PatentIndex Score
50
Cited by
30
References
12
Claims

Abstract

A method and system to maintain portable computer data secure and an authentication token for use in the system are provided. The present invention provides for fine-grained authentication and full security of a laptop file system. The laptop disk is encrypted and each time data is fetched from the disk the laptop sends a short message requesting a decryption key from an authentication token worn or associated with the proper laptop user. If the user and his/her token are "present," then access is allowed. If the user and his/her token are not "present" (i.e., within a predetermined radius), then access is disallowed and all in-memory data is flushed to the disk. The user wears the small authentication token that communicates with the laptop over a short-range, wireless link. Whenever the laptop needs decryption authority, it acquires it from the token; authority is retained only as long as necessary.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
       1. A system to maintain data stored on a portable computer secure, the system comprising:
 an authorization client for use on the portable computer for making requests; 
 a security device to be associated with an authorized user of the portable computer and including an authorization server for supplying responses to the requests; 
 a communication subsystem for wirelessly communicating the requests and the responses to the server and the client, respectively, within a range; and 
 a cryptographic subsystem for use on the portable computer for encrypting the data to obtain corresponding encrypted data when the security device is outside the range of the communication subsystem and for decrypting the encrypted data when the security device is back within the range; 
 wherein the requests include cryptographic requests for cryptographic information and wherein the server supplies the cryptographic information in response to the cryptographic requests and wherein the cryptographic subsystem utilizes the cryptographic information to either encrypt or decrypt the data. 
 
     
     
       2. The system as claimed in  claim 1  wherein the requests include polling requests. 
     
     
       3. The system as claimed in  claim 1  wherein the cryptographic information includes keys. 
     
     
       4. The system as claimed in  claim 3  wherein the keys are encrypted. 
     
     
       5. The system as claimed in  claim 3  wherein the keys include user and group keys. 
     
     
       6. The system as claimed in  claim 1  further comprising a mechanism for establishing a binding between the portable computer and the security device to ensure that the security device only responds to a portable computer with a valid binding. 
     
     
       7. The system as claimed in  claim 1  wherein the security device is an authorization token. 
     
     
       8. The system as claimed in  claim 1  wherein the computer has a low speed memory and high speed memory and wherein the data stored in the high speed memory is not encrypted and the data stored in the low speed memory is encrypted. 
     
     
       9. The system as claimed in  claim 1  wherein the cryptographic subsystem includes encrypted keys and wherein the cryptographic information includes keys for decrypting the encrypted keys. 
     
     
       10. The system as claimed in  claim 1  wherein the requests including the polling requests are encrypted. 
     
     
       11. A method to maintain data stored on a portable computer secure, the method comprising:
 providing an authorization client for use on the portable computer for making requests; 
 providing a security device to be associated with an authorized user of the portable computer and including an authorization server for supplying responses to the requests; 
 wirelessly communicating the requests and the responses to the server and the client, respectively, within a range; 
 encrypting the data to obtain corresponding encrypted data when the security device is outside the range; and 
 decrypting the encrypted data when the security device is back within the range; 
 wherein the requests include cryptographic requests for cryptographic information and wherein the server supplies the cryptographic information in response to the cryptographic requests and wherein the cryptographic information is used to either encrypt or decrypt the data. 
 
     
     
       12. The method as claimed in  claim 11  further comprising establishing a binding between the portable computer and the security device to ensure that the security device only responds to a portable computer with a valid binding.

Join the waitlist — get patent alerts

Track US7302571B2 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.